> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/use-the-cortex-xdr-agent-app-for-android.md).

# Use the Cortex XDR Agent App for Android

Learn about using Cortex XDR agent app for Android after you have installed it.

The Cortex XDR agent app for Android offers these features:

* Scan apps, view scan history and scan results
* View app protection status
* Take action on malware, blocked apps, and unknown files
* Analyze URLs

The following table explains how to use these features:

| Feature                                                 | How to use it                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | More details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| View latest events                                      | **Menu icon+Home**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | The Cortex XDR home page displays the latest events. To view more details about an event, tap it.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Scan installed apps                                     | **Menu icon+Scan**, and then tap **Scan Now**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | <p>Cortex XDR scans all apps and requests verdicts for the apps. After you install Cortex XDR for Android, scan all apps installed on the Android device.<br><br>For each app Cortex XDR detects, it generates a hash for the file and requests the file verdict from Cortex XDR. If necessary, Cortex XDR queries WildFire for the verdict.<br><br>After the initial scan, Cortex XDR inspects apps immediately as they are installed, and as automated or manual scans occur. At regular intervals, Cortex XDR also rechecks all verdicts with WildFire.<br><br>For unknown apps, Cortex XDR sends the unknown file to Cortex XDR for in-depth analysis.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| View scan history                                       | **Menu icon+Scan**, and then tap **Scan history**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | <p>Cortex XDR displays a history of scans, which includes the date and time the scan ran, and the number of apps identified as malware (red) or as benign (green).<br><br>Optionally, to see more details about a scan, tap the desired row in the scan history.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| View scan results and protection status                 | <p><strong>Menu icon+Scan Results</strong><br><br>• View a complete list of installed apps and their statuses:<br>• In the <strong>Related Apps</strong> area, tap <strong>All</strong>.<br>• By default, the Cortex XDR page orders the apps by the most recent installation date.<br>• Filter apps:<br>• In the <strong>Related Apps</strong> area, tap the desired category (<strong>Malware</strong>, <strong>Allowed</strong>, or <strong>Pending</strong>).<br>• View more details about an app:<br>• In the <strong>Related Apps</strong> area, scroll to the desired app and tap it.</p> | <p>The scan results page displays the status of anti-malware protection, a numerical summary, and a list of the apps installed on the Android endpoint. Cortex XDR automatically refreshes the summary when it discovers new apps and receives updated or changed verdicts.<br><br>The following categories are used to classify apps:<br><br>• <strong>Malware:</strong> Cortex XDR blocks an app if the app has a Malware verdict as determined by WildFire, is blocked by a hash exception policy, or is unknown. To block unknown apps, the administrator must enable Cortex XDR to Block files with unknown verdict in the Malware Security Profile for Android endpoints. When Cortex XDR blocks an app due to a hash exception policy, Cortex XDR shows the app with a Block status.<br><br>• <strong>Allowed:</strong> Cortex XDR allows an app to run if the app has a Benign verdict as determined by WildFire, or is signed by a trusted signer. The administrator can add signers to the allow list as part of the Malware Security Profile for Android endpoints.<br><br>• <strong>Pending:</strong> A pending app is an app that has not yet received an official WildFire verdict. Unknown apps are allowed to run only when this feature is enabled in the Cortex XDR policy.</p> |
| Take action on malware, blocked apps, and unknown files | <p>If Cortex XDR identifies a malicious or suspicious (unknown) app, Cortex XDR prompts you with the following actions:<br><br>• <strong>Stop:</strong> Opens the corresponding settings page of that app, where you can stop the app.<br><br>• <strong>Uninstall:</strong> Remove the malware from the Android device. From the scan results page, go to Related Apps+Malware, and then tap the trash can icon for the app that you want to remove.</p>                                                                                                                                         | When you attempt to run a malicious app, a blocked app (as defined by a hash exception policy), or an unknown app, Cortex XDR automatically blocks the app from running according to your organization's policy. The administrator can configure Cortex XDR to treat grayware in the same way as it treats malware.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Analyze URLs                                            | For text that includes links to URLs, select the text and share it using Android's Share option, and then share it with Cortex XDR.                                                                                                                                                                                                                                                                                                                                                                                                                                                              | <p>Use the Cortex XDR app to check URLs for safety before you use or share them.<br><br>Cortex XDR will analyze the URL that you shared with it, and will then display the verdict, along with additional related information, depending on the verdict, such as Risk Level and Category.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-agent-android-guide/9.2/use-the-cortex-xdr-agent-app-for-android.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
